IT Assets: add role-based auth system and portal user sync
Auth: - Fix local login (was redirecting to portal; now authenticates AdminUser directly) - Portal SSO still takes priority in production via nginx headers Role system (admin | editor | readonly): - New app/utils/decorators.py with editor_required and admin_required decorators - All write routes protected with editor_required (create/edit/delete/import/mask) - Settings user management protected with admin_required - Sidebar hides write-only links for readonly users - Dashboard quick actions and list page buttons hidden for readonly Settings page: - Role colour badges (admin=red, editor=blue, readonly=grey) - Inline role changer per user (dropdown auto-submit) - Reset password modal per user - Delete user button with confirmation - Add user form includes role selector with legend Portal user sync: - New /internal/sync-user endpoint receives user pre-creation from portal - INTERNAL_SYNC_SECRET added to config - portal/config.py: added internal_url for itassets app so _sync_user_to_app works
This commit is contained in:
@@ -4,6 +4,7 @@ from flask import (Blueprint, render_template, redirect, url_for,
|
||||
flash, request, current_app, jsonify)
|
||||
from flask_login import login_required, current_user
|
||||
from app.extensions import db
|
||||
from app.utils.decorators import editor_required
|
||||
from app.models.asset import Asset, ASSET_TYPES, ASSET_STATUSES
|
||||
from app.models.audit_log import AuditLog
|
||||
from app.models.compliance_check import ComplianceCheck
|
||||
@@ -82,6 +83,7 @@ def index():
|
||||
# ------------------------------------------------------------------
|
||||
@bp.route('/new', methods=['GET', 'POST'])
|
||||
@login_required
|
||||
@editor_required
|
||||
def create():
|
||||
if request.method == 'POST':
|
||||
sn = request.form.get('serial_number', '').strip()
|
||||
@@ -204,6 +206,7 @@ def detail(asset_id):
|
||||
# ------------------------------------------------------------------
|
||||
@bp.route('/<int:asset_id>/edit', methods=['GET', 'POST'])
|
||||
@login_required
|
||||
@editor_required
|
||||
def edit(asset_id):
|
||||
asset = Asset.query.get_or_404(asset_id)
|
||||
|
||||
@@ -267,6 +270,7 @@ _COMPLIANCE_FIELDS = {
|
||||
|
||||
@bp.route('/<int:asset_id>/compliance', methods=['POST'])
|
||||
@login_required
|
||||
@editor_required
|
||||
def update_compliance(asset_id):
|
||||
asset = Asset.query.get_or_404(asset_id)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user